<?php
$uname = isset($_POST['uname']) ? ($_POST['uname']) : '';
$pass = isset($_POST['pass']) ? ($_POST['pass']) : '';
$dsn="mysql:host=127.0.0.1;dbname=tianshl_as";
$user="root";
$psw="root";
$pdo=new PDO($dsn,$user,$psw);
$res=$pdo->query("select * from `zcb` where uname='$uname' and pass='$pass'")->fetch();
// echo "<pre>";
// var_dump($res);
if ($res) {
    header('location:show.html');
}
